Please do not open a public issue for security problems.
Instead, use GitHub's private vulnerability reporting: open this repository on
GitHub, go to the Security tab, and choose Report a vulnerability
(direct path: https://github.com/<owner>/<repo>/security/advisories/new).
Please include:
- the contract name and a link or snippet of the relevant code,
- a concrete description of the impact (what an attacker could do),
- any reproduction steps, test case, or transaction.
We aim to acknowledge reports within 72 hours and will credit researchers in published advisories when desired.
All contracts under src/ in this repository, as deployed on Robinhood Chain
mainnet (chain ID 4663) and testnet (chain ID 46630), are in scope.
Once a fix is released we will publish a GitHub Security Advisory with credits, and appreciate the opportunity to coordinate timing before public disclosure.